Skip to main content

Share story

Security

Cybercriminals allegedly hacked tens of thousands of Fortinet firewalls used by major companies all over the world

Cybercriminals allegedly hacked tens of thousands of Fortinet firewalls used by major companies all over the world Image: Primary
Cybercriminals have compromised tens of thousands of Fortinet firewalls and VPNs used by major companies all over the world, according to cybersecurity firms Hudson Rock and SOCRadar. The widespread hacking campaign, which is ongoing and has been dubbed FortiBleed, does not appear to involve abusing any unknown vulnerability in the targeted devices. Companies may not be changing passwords to the firewall or making sure that the credentials they use for sensitive systems exposed on the internet are not already known by hackers. In the campaign, hackers first use automated tools to scan the internet for exposed Fortinet firewalls and VPNs. They then break into the devices using lists of previously known passwords. Once a device is compromised, the hackers use it as a listening post, monitoring traffic passing through and collecting any additional credentials that flow by, which are then fed back into the scanner to compromise even more devices, SOCRadar wrote in its report. Hudson Rock said it found evidence that suggests more than 73,000 unique Fortinet URLs have been hacked, while SOCRadar said the total of hacked devices is more than 30,000. The hacked companies include Accenture, Comcast, Foxconn, Lenovo, Oracle, Samsung, Siemens, and PwC, according to Hudson Rock. The countries with the most affected devices are India, the United States, Taiwan, and Mexico, though victims are located all over the world. The most affected industries are IT services, construction materials, and telecommunications, according to Hudson Rock. Government agencies are also among the victims, per SOCRadar. The group behind the hacking campaign appears to be Russian-speaking. Fortinet said it is aware of a reported third-party credential-harvesting campaign targeting Fortinet firewalls and VPN gateways. The company said based on its analysis the data involved is a resharing of data from previous incidents as well as bruteforcing of credentials and is not related to any recent incident or advisory. The reports are based on the discovery of a list of credentials for Fortinet devices and associated companies. The hacking campaign was first reported by security researcher Bob Diachenko. Independent cybersecurity researcher Kevin Beaumont said he analyzed the data and confirmed the data is legit.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from TechCrunch, cybersecurity and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Infrastructure
Security Infrastructure

CISA adds two exploited Check Point flaws to federal fix list

The U.S. Cybersecurity and Infrastructure Security Agency added two Check Point Security Gateway flaws to its list of known exploited vulnerabilities and told federal agencies to apply fixes or mitigations by September 25. Check P...

Security Infrastructure
Security Infrastructure

Analysis identifies two flaws behind exploited MikroTik router takeover chain

CERT Polska has identified the two RouterOS SSH flaws behind a previously reported attack that can give intruders administrative control of exposed MikroTik routers without completing authentication. One flaw lets a connection rea...

Security
Security

FBI investigates ShinyHunters claim of employee data theft

The FBI is investigating ShinyHunters' claim that it stole personal information about thousands of current and former agency employees after exploiting a previously unknown flaw on FBIJobs.gov, Ars Technica reported. The group als...